acr — Authentication Context Class Reference
Location: payload · Format: string
Indicates the authentication method/assurance level actually used (e.g. password-only vs. multi-factor), as a string agreed between OP and RP out of band. Only meaningful to enforce when the RP requested a specific level via acr_values in the auth request.
Defined in OpenID Connect Core 1.0 §2.
Decode a JWT and inspect its acr claim in the TokenPrism debugger — free, entirely in your browser.